Showing 5 vulnerabilities on this page for PyCharm

Signals CISA KEV Ransomware Nuclei
JetBrains vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:JetBrains PyCharm Arbitrary Code Execution via Malicious Python Executable on Untrusted Project Open

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CWE-829Jul 23, 2026
CVSS8.6v3.1EPSS0.126%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains PyCharm Stored Cross-Site Scripting in Jupyter Notebook Markdown Cells

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

CWE-79May 29, 2026
CVSS6.1v3.1EPSS0.181%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains PyCharm DOM-based Cross-Site Scripting in Jupyter Viewer Page

In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

CWE-79Feb 9, 2026
CVSS8.2v3.1EPSS0.205%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7,

CWE-522Jun 10, 2024
CVSS9.3v3.1EPSS3.84%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

CWE-1327CWE-668Apr 28, 2022
CVSS3.0v3.1EPSS0.382%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX